Skip to content

China Data Export Security Assessment Measures

In force China · In force Sep 1, 2022 · no upcoming deadlines

Deadlines

DateWhat happens
Mar 1, 20233 years agoRemediation window for existing transfers endstentative
Sep 1, 20224 years agoSecurity assessment measures take effect

Summaries for reference, not legal advice. Check the official text.

What it does

Sets the CAC security assessment that must be passed before certain data leaves China, including exports of important data and large-scale personal information exports. Data handlers must run a self-assessment, then apply through the provincial CAC for a national CAC review. Transfers already under way had six months to come into compliance.

Who it applies to
Data handlers exporting important data, CII operators exporting personal information, and handlers exporting personal information above the volume thresholds set by the CAC.
Penalties
Handled under the CSL, DSL and PIPL. PIPL fines reach RMB 50 million or 5% of prior-year turnover for serious violations.
Enforced by
Cyberspace Administration of China (CAC)
Official name
Measures for the Security Assessment of Outbound Data Transfers
Citation
CAC Order No. 11
Topics
data-residency, privacy, cybersecurity
Verified 2026-09-25 gov.cn
Research notes

The 2024 Provisions on Promoting and Regulating Cross-Border Data Flows (cn-cross-border) raised the thresholds and extended approval validity from 2 to 3 years. Signed 2022-07-07.

Related

Questions about China Data Export Security Assessment Measures
What are the China Data Export Security Assessment Measures compliance deadlines?
Sep 1, 2022: Security assessment measures take effect. Mar 1, 2023: Remediation window for existing transfers ends (tentative).
When does China Data Export Security Assessment Measures take effect?
China Data Export Security Assessment Measures took effect on Sep 1, 2022.
Who does China Data Export Security Assessment Measures apply to?
Data handlers exporting important data, CII operators exporting personal information, and handlers exporting personal information above the volume thresholds set by the CAC.
What are the penalties under China Data Export Security Assessment Measures?
Handled under the CSL, DSL and PIPL. PIPL fines reach RMB 50 million or 5% of prior-year turnover for serious violations.

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.